OnTrac notifies customers of data breach after network hack

OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers.

The incident was detected on March 23, and an internal investigation revealed that the attacker accessed certain files between March 20 and 22.

Apart from names, it is unclear what type of information was exposed, as the company redacted the data elements in the notification sample shared with authorities.

OnTrac is a private American parcel-delivery company specializing in “last-mile” e-commerce deliveries, formed in 2021 from the merger of OnTrac Logistics and LaserShip.

The firm operates at 102 locations across 35 states, covering roughly 70% of the U.S. population, and working with more than 7,000 independent delivery contractors.

In response to the security incident, OnTrac contracted a third-party specialist to help determine the scope of the breach and took steps to “ensure the data described above was re-secured and not distributed.”

This statement suggests a possible agreement between the firm and the attackers, typically a ransom payment, to make sure that the customer information is not leaked.

“We are not aware of any fraud or publication of stolen information resulting from this incident, nor do we have any reason to believe any such misuse of information will occur,” OnTrac says in the notification.

To help exposed customers mitigate the risks that may arise from the exposure of their sensitive data, OnTrac is offering free-of-charge access to a 12-month credit monitoring and identity protection service via CyberScout, with a 90-day enrollment deadline.

Recipients of the letter are also recommended to review their credit reports and account statements, and consider placing a free fraud alert or credit freeze if the risk is deemed significant.

BleepingComputer has contacted OnTrac to learn more about the attack, the number of impacted clients, and whether a ransom was paid, but we have not heard back by publication time.

At the time of writing, no ransomware or data extortion threat groups have taken responsibility for the attack.

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Ernst & Young discloses data breach after support system hack

Healthtech firm Xolis suffers data breach impacting 1.4 million people

Upbound says hack caused $13 million in fraudulent Acima leases

Medtronic notifies customers impacted by ShinyHunters data breach

LastPass confirms data breach in Klue supply chain attack

OpenAI confirms ChatGPT is down worldwide

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Microsoft blames massive Microsoft 365 outage on maintenance bug

Your Scanners Are Green. Your Pipeline Might Not Be. Here’s How to Close the Gap.

Calculate what you’d save by replacing your MDR.

AI agents can speed up ransomware attacks. See how Acronis helps reduce the risk.

Overdue a password health-check? Audit your Active Directory for free

Rev5 is ending. See what your FedRAMP 20x transition really requires

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.